Guides & Documentation
Everything you need to implement cookie consent on your website
Showing 203 guides in Compliance
Building a TCF CMP That Passes IAB Validation
What it takes for a Consent Management Platform to pass IAB Europe's TCF checks: a registered CMP ID, a cleanly decodable TC String, event-listener delivery, and encoding against the right GVL version.
Switzerland's Revised FADP: Cookie Consent in 2026
Switzerland isn't in the EU, and its cookie rules follow a different logic: risk-based, opt-out for low-risk cookies, opt-in for advertising and profiling. Here's how the revised FADP and the 2025 FDPIC guidance actually work.
Switching Analytics or Marketing Vendors? Handle the Cookie Changes
Replacing one tracking tool with another quietly rewrites your cookie inventory and your data recipients. Here's how to swap vendors without leaking trackers or orphaning cookies.
SvelteKit Cookie Consent: The 2026 Setup Guide
SvelteKit renders on the server and hydrates on the client, which means a tracker in app.html or an onMount call can fire before consent. Here's where the consent loader belongs, how to block scripts until opt-in, and how to check consent in hooks.server.ts.
Cookie Consent for Streaming and Video Sites: The VPPA Problem
A 1988 law written for video-rental stores now drives class actions against any website that puts a tracking pixel near a video player. Here's how streaming and video sites handle the Video Privacy Protection Act alongside GDPR and state consent rules.
South Korea's PIPA: Cookie Consent Rules for 2026
South Korea is one of the strictest consent regimes on the planet, and its regulator proves it. The PIPC has fined Google and Meta a combined 100 billion won for behavioral-ad tracking without consent. Here's how PIPA treats cookies after the 2023 overhaul.
Social Embeds and Consent: The Click-to-Load Pattern
Instagram, X, TikTok, and Facebook embeds load third-party scripts and set cookies before anyone interacts. A CJEU ruling makes you a joint controller for that data flow. Click-to-load fixes it.
SOC 2 and Privacy: What the Report Says About Cookies
SOC 2 is the report enterprise buyers ask for first, but its Privacy category is the one most companies skip. Here's what SOC 2 actually attests, how the Privacy criterion works, and why your cookie consent records show up in the audit.
Singapore PDPA Cookie Consent: 2026 Guide
Since October 2022, Singapore's regulator can fine organisations up to 10% of local turnover for data breaches. Here's how the PDPA treats cookies, how deemed consent works, and why ignored browser settings don't count as agreement.
How to Set Up Google Consent Mode With a CMP
Consent Mode v2 has been required since March 2024 to keep Google ad and measurement features working in the EEA. Here's the end-to-end setup wiring your CMP to Google's seven consent signals, step by step.
Sensitive Data Under US State Privacy Laws in 2026
Health data, precise location, and other sensitive categories get special treatment under US state laws, and the rules split between opt-in consent and a right to limit. Here is how to handle them.
Safari ITP Explained for Marketers
Safari blocks every third-party cookie and deletes JavaScript-set cookies after seven days. Here's what Intelligent Tracking Prevention does to your measurement, and what it doesn't.
ROPA for Cookies: Building an Article 30 Record for Your Trackers
GDPR Article 30 requires most organisations to keep a written record of their processing activities. Here's how to turn a cookie and tracker inventory into ROPA entries a supervisory authority will accept.
The Right to Be Forgotten: Handling Erasure Requests in Practice
The right to erasure is not a delete button, and it is not absolute. Here is how to work an Article 17 request end to end: the six grounds, the exemptions that let you keep data, backups, the Article 19 downstream notification, and the CCPA right to delete in parallel.
Cookie Consent for Job Boards and Recruitment Sites
The EU AI Act makes recruitment AI high-risk from August 2026, and the ICO has put automated hiring decisions on its enforcement list. Here's how job boards and career sites should handle cookie consent for candidate data.
Quebec's Law 25: Cookie Consent Rules for 2026
Federal PIPEDA is flexible about cookies. Quebec's Law 25 is not. Section 8.1 requires profiling and tracking technology to be switched off by default, and the CAI can levy penalties up to CAD $25 million. Here's the Quebec-specific model, layer by layer.
Your Quarterly Cookie Consent Review: A Recurring Checklist
A full audit once a year isn't enough when your site changes weekly. Here's a lighter quarterly review that keeps consent current between audits, with a repeatable agenda.
How to Build a Privacy Trust Center That Closes Deals
A trust center turns your three-week security questionnaire into a link. Here's what to publish openly, what to gate behind an NDA, and how your subprocessor list and consent records fit, so buyers self-serve their due diligence.
Privacy Sandbox Is Over: What Google's 2025 Shutdown Means for Consent
On 17 October 2025 Google retired most Privacy Sandbox technologies and kept third-party cookies in Chrome. Here's the verified timeline and why consent banners now matter more, not less.
How to Build a Privacy Request Intake Form That Complies
The intake form is where a privacy request is won or lost. Get the fields, methods, and routing right and the rest of the process runs itself. Here is what the CCPA and GDPR require, the fields to capture, and the traps that turn a form into a dark pattern.
POPIA Cookie Consent in South Africa: 2026 Guide
South Africa's Information Regulator issued its first POPIA fine (R5 million) in 2023 and has warned that more are coming. Here's how POPIA treats cookies, what section 69 means for tracking, and what the 2025 amended Regulations changed.
Do Plausible & Fathom Need Consent? Cookieless, Explained
Cookieless analytics like Plausible and Fathom store nothing on the device, so the ePrivacy cookie rule generally doesn't apply and you can usually skip the banner. But GDPR still does, and no EU regulator has formally certified them. Here's the honest picture.
Cookie Consent for Pharma and Life Sciences Websites
Drug makers usually aren't HIPAA covered entities, but their sites still handle health data that GDPR treats as a special category and that Meta throttles automatically. Here's how pharma and life-sciences companies run cookie consent across brand sites, HCP portals, and adverse-event forms.
Oregon Consumer Privacy Act: Cookies in 2026
Oregon's privacy law turned on two things in 2026: a universal opt-out mandate that went live January 1, and the end of the cure period on the same day. It also gives residents a right most states don't, the names of the specific third parties that got their data.